Privacy Policy
ComplyFlo Waste LLC · Last updated: May 16, 2026 · Effective upon posting
1. Overview
ComplyFlo provides workflow, recordkeeping, and reporting software for environmental and operational use cases, including but not limited to wastewater facilities, municipal solid waste sites, compost sites, haulers, used cooking oil operations, and related industries. This Privacy Policy is intended to cover current and future ComplyFlo offerings.
This Privacy Policy should be read together with the ComplyFlo Terms and Conditions.
2. Scope
This Privacy Policy applies to:
- –Visitors to the ComplyFlo website
- –Trial users, subscribers, customers, and authorized users of the Services
- –Individuals whose information is submitted to the Services by customers or users
- –Business contacts, support requestors, implementation contacts, and vendor contacts
This Privacy Policy does not apply to third-party websites, systems, applications, or services that may integrate with or link to the Services. Those third parties have their own privacy practices and policies.
3. Categories of Information Collected
ComplyFlo may collect the following categories of information, depending on how the Services are used:
A. Account and Contact Information
- –Name, business name, and job title
- –Email address and phone number
- –Mailing address
- –Username and authentication details
B. Customer Operational and Reporting Data
Depending on the customer use case, ComplyFlo may process operational, reporting, and recordkeeping data submitted by customers — including facility identifiers, permit numbers, transporter identifiers, manifests, waste stream records, environmental measurements, disposal records, route or pickup information, uploaded forms, logs, attachments, and related workflow records.
This category may include personal information to the extent customer records contain names, phone numbers, signatures, email addresses, driver information, operator information, contact records, or other information associated with identifiable individuals.
C. Billing and Transaction Information
- –Billing contact details and subscription details
- –Payment-related information and invoices
- –Transaction history
D. Usage and Device Information
- –IP address, device type, browser type, and operating system
- –Referring URLs, pages viewed, and app activity
- –Date and time of access
- –Crash logs and diagnostic information
- –Cookies and similar technologies
E. Communications and Support Information
- –Messages sent through contact forms, emails, and support requests
- –Chat messages and meeting notes
- –Implementation and training communications
F. Integration and Third-Party Source Data
If a customer connects third-party tools, ComplyFlo may receive data from those systems — such as SCADA systems, spreadsheets, laboratories, accounting tools, GPS or route systems, cloud storage tools, or other customer-authorized data sources.
4. How Information Is Collected
ComplyFlo may collect information:
- –Directly from users, customers, and website visitors
- –From customer uploads, forms, imports, and manual entry
- –Through integrations and APIs authorized by the customer
- –Automatically through cookies, analytics tools, logs, and similar technologies
- –From service providers, implementation partners, payment providers, or other third parties acting on the customer's instructions or in connection with the Services
5. Purposes of Processing
ComplyFlo may use information for the following purposes:
- –To provide, maintain, host, secure, and improve the Services
- –To create and manage accounts and subscriptions
- –To authenticate users and manage access permissions
- –To process uploads, records, reports, exports, dashboards, and integrations
- –To provide customer support, onboarding, implementation, and training
- –To communicate about accounts, service updates, invoices, security matters, and support issues
- –To monitor usage, troubleshoot problems, analyze performance, and improve product functionality
- –To protect against fraud, abuse, unauthorized access, and security incidents
- –To comply with legal obligations, respond to lawful requests, and enforce agreements
- –To conduct limited marketing and business development activities, subject to applicable law and user choices
6. Legal Bases and Texas Privacy Considerations
For customers and users in Texas, ComplyFlo may be subject to the Texas Data Privacy and Security Act (TDPSA) depending on the company's size, activities, and the types of personal data processed. TDPSA generally requires a reasonably accessible privacy notice, data minimization, reasonable security measures, and processes for consumer rights requests, subject to the law's applicability thresholds and exemptions.
ComplyFlo may process personal data when reasonably necessary to provide requested services, operate the business, comply with law, protect security, fulfill contractual obligations, or pursue legitimate business purposes consistent with applicable law.
7. Cookies and Analytics
ComplyFlo may use cookies, pixels, SDKs, local device identifiers, and similar technologies to operate the website and Services, remember preferences, authenticate sessions, improve performance, understand engagement, and support analytics.
8. How Information Is Shared
ComplyFlo does not sell personal information. We may share information in the following circumstances:
A. Service Providers and Vendors
With hosting providers, infrastructure providers, customer support vendors, analytics providers, payment processors, communications providers, consultants, and other vendors that process information on ComplyFlo's behalf. These include Supabase (Lovable Cloud) for database and hosting, Stripe for payment processing, and Google (Gemini) for AI-assisted data extraction.
B. Customer-Directed Sharing
With third-party systems, integrations, consultants, regulators, laboratories, contractors, or other recipients when directed or authorized by the customer or user.
C. Business Transactions
In connection with a merger, acquisition, financing, sale of assets, reorganization, bankruptcy, or similar corporate event. We will notify active subscribers before their information becomes subject to a different privacy policy.
D. Legal and Safety Reasons
To comply with law, subpoena, court order, government request, enforcement action, or audit, or to protect the rights, safety, property, users, the public, or the Services.
E. Affiliates and Advisors
With affiliated entities, insurers, auditors, lawyers, accountants, and professional advisors, as reasonably necessary for business operations and legal compliance.
9. Customer-Controlled Data and Controller / Processor Roles
In many cases, ComplyFlo acts as a service provider, processor, or contractor on behalf of business customers who control the data loaded into the Services. In those cases, the customer determines the purposes and means of processing certain customer-controlled information, and individuals may need to direct some privacy requests to the relevant customer.
ComplyFlo may also act as a controller for data relating to its own website visitors, business contacts, account administrators, billing contacts, and product usage analytics, depending on the context.
10. Data Retention
ComplyFlo may retain personal information and customer data for as long as reasonably necessary to provide the Services, maintain business records, support legitimate business operations, comply with contracts, resolve disputes, enforce agreements, protect security, satisfy legal obligations, and retain necessary audit trails.
Retention periods may vary depending on:
- –The type of information and customer subscription status
- –Applicable legal, tax, accounting, environmental, or contractual requirements
- –Backup, archival, and disaster recovery practices
- –Whether deletion would impair fraud prevention, security, dispute resolution, or audit integrity
When information is no longer needed, ComplyFlo may delete, aggregate, or de-identify it, subject to legal and operational requirements.
11. Data Security
ComplyFlo uses commercially reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, disclosure, alteration, and destruction. Such measures may include:
- –Access controls and role-based permissions
- –Encryption in transit (TLS) for all data transmitted between your browser and our servers
- –Database-level row-level security enforced through Supabase
- –Secure authentication and multi-factor authentication support
- –Audit logging of every edit, approval, and status change
- –Vendor management, monitoring, backups, and incident response processes
12. International and Cross-Border Data Transfers
ComplyFlo may store or process information in the United States or other jurisdictions where ComplyFlo or its service providers operate. If ComplyFlo serves users outside the United States in the future, additional disclosures, safeguards, or transfer mechanisms may be required depending on where the data originates and where it is processed.
13. Privacy Rights and Choices
Depending on applicable law and your location, you may have rights to request access, correction, deletion, portability, or restrictions relating to your personal data, and may have the right to appeal certain privacy decisions.
To exercise applicable privacy rights, submit a request using the contact information in Section 18 below. ComplyFlo may need to verify your identity and authority before processing a request, and may deny or limit requests where permitted by law — including where the data is controlled by a business customer or must be retained for legal, security, or operational reasons.
14. Children's Privacy
The Services are intended for business and operational use and are not directed to children. ComplyFlo does not knowingly collect personal information directly from children in a manner requiring parental consent under applicable law. If ComplyFlo learns that it has collected personal information from a child in violation of applicable law, ComplyFlo may take steps to delete that information.
15. Public, Regulatory, and Customer Disclosures
ComplyFlo customers may use the Services in industries that involve public reporting, inspections, records requests, regulatory audits, or government submissions. Some information handled through the Services may therefore be disclosed by customers, regulators, or third parties under applicable law, permit rules, subpoenas, open records laws, or other legal processes.
16. Third-Party Services and Links
The Services may contain links to third-party websites, portals, forms, maps, payment pages, or integration partners. ComplyFlo is not responsible for the privacy practices of those third parties. Users should review the privacy notices of third-party services before providing information to them.
17. Changes to This Privacy Policy
ComplyFlo may update this Privacy Policy from time to time. The revised version will become effective when posted or on the effective date stated in the updated policy.
When we make material changes, we will update the "Last updated" date at the top of this page and send an email notification to account administrators. Where required by law, we will provide additional notice or obtain consent for material changes.
18. Contact Information
Questions, privacy requests, and privacy complaints should be directed to:
ComplyFlo Waste LLC
29607 Pewter Run Lane
Katy, TX 77494
Email: info@complyflowaste.com
Website: complyflowaste.com
We will respond to all privacy-related inquiries within 30 days.